Cisco Talos identified UAT-7237, a Chinese-speaking APT group targeting Taiwanese web hosting infrastructure since 2022. Utilizing open-source tools, UAT-7237 focuses on long-term persistence, employing a customized Shellcode loader called "SoundBill" for malicious operations. Their tactics include exploiting unpatched servers, using SoftEther VPN for access, and deploying credential extraction tools like Mimikatz. Recommendations for detection include Cisco Secure Endpoint and Snort rules. IOCs are provided for further analysis.
